Simplify Logo

Full-Time

Sr. SRE Security Engineer

Confirmed live in the last 24 hours

DoubleVerify

DoubleVerify

1,001-5,000 employees

Digital advertising verification and analytics services

Data & Analytics
Enterprise Software

Compensation Overview

$102k - $202kAnnually

+ Bonus + Commission + Equity + Benefits

Senior, Expert

New York, NY, USA

Category
Cybersecurity
IT & Security
Required Skills
PowerShell
Bash
Python
Communications
Management
AWS
JIRA
Terraform
Ansible
Development Operations (DevOps)
Linux/Unix
Google Cloud Platform
Requirements
  • 7+ years as a Security Engineer \ SRE \ DevOps engineer with a passion for security and doing things right.
  • 4-6 years of related experience in vulnerability management and remediation
  • Hands-on Experience with patching and hardening Linux, Windows, and ESXi servers is essential.
  • Experience with building, configuring, and managing patch management tools.
  • High proficiency within cloud environments - with a preference for GCP and AWS.
  • Proficiency in automation and configuration management tools (e.g Ansible, Terraform, Puppet).
  • Proficiency in scripting languages, including Bash, Python and/or PowerShell.
  • 1-2 years developing playbooks, runbooks, and troubleshooting technical issues.
  • Ability to grasp new technologies quickly and prioritize and multitask on multiple responsibilities
  • Effective documentation skills, including technical diagrams and written descriptions.
  • Experience analyzing vulnerabilities and adjusting the risk rating/severity dependent on internal factors.
  • Experience defining Operating System Baseline Configuration standards such as the Center for Internet Security (CIS) Critical Security Controls Scanning within various scanning technologies and working with appropriate teams to remediate and report on the results.
  • Proficient in firewall management, with hands-on experience in configuration and optimization to ensure network security.
  • Familiarity with ITSM solutions, including platforms like Jira and Freshdesk.
  • Clear communication and collaboration abilities for cross-functional teamwork.
  • Critical thinking and ability to balance security requirements with mission needs.
  • Exceptional organizational skills demonstrated through adept autonomy, independent work, collaborative teamwork, and an unwavering professional demeanor. This extends to adept tracking and comprehensive reporting of work and time allocations.
Responsibilities
  • Work closely and in full coordination with multiple departments, SRE, Operation, DevOps, and Network teams to produce a highly secure posture.
  • Handle, prioritize, and effectively bring security vulnerabilities to resolution for Production, Staging, and Dev environments; you will play an active part in resolving them.
  • Develop, update, and guide procedures for security enhancements, test these procedures, and facilitate their handover to the operations team for complete remediation.
  • Review vulnerabilities and data from various sources (e.g., vulnerability scanning, penetration testing) across different technologies and environments to assess the risk level to business assets and help remediate them.
  • Build, configure, and manage vulnerability management tools within company environments, serving as the subject matter expert for vulnerability management queries.
  • This position will be the liaison between the IT Security Team and various SRE, DevOps, Network, and Operation teams and must be able to provide technical remediation details or workarounds, help track and identify asset inventory, log work tickets and exceptions, and research vulnerability findings.
  • Be the go-to expert for implementing security agents on Production, Staging, and Dev environments, ensuring the security of these assets throughout their lifecycle. (Such as configuring and troubleshooting any security solution agent & authentication issues).
  • Proficiently managed security aspects of Linux, Windows, and ESXi servers, including patch management and fundamental security practices.
  • Execute OS patching and work towards automating this process, following a thorough testing and deployment cycle across development, staging, and production environments, which include proper notification and auditing process.
  • Implement technical solutions to automate repetitive tasks.
  • Undertake notifications and audits related to security work and maintain a proactive and organized approach.
  • Manage and follow up on tickets related to remediation or hardening requests.
  • Provide analysis of Information Security vulnerabilities and determine true or false positives, and work with appropriate teams for remediation.
  • Engage actively in Proof of Concept initiatives to assess and onboard novel security solutions. Offer technical expertise to ensure effective deployment and alignment with security goals. Document findings comprehensively and conduct thorough comparisons of potential solutions, aiding the team in making informed decisions.
  • Help focus the engineering teams on working on high-value security issues and avoid toiling on non-security issues.
  • Demonstrate self-management skills to effectively track and report on work and time allocation.

DoubleVerify ensures the quality and effectiveness of digital advertising for major brands. The company provides verification and analytics services that help brands, advertisers, platforms, and publishers confirm that their ads are seen by real people, are placed in safe environments, and effectively reach their target audiences. Their services include checking ad viewability, preventing fraud, and ensuring brand safety by using advanced technology and dedicated teams to identify and combat fraud schemes. Unlike many competitors, DoubleVerify focuses on delivering comprehensive verification solutions that protect brand reputation across various devices and channels. The goal of DoubleVerify is to help clients maximize their advertising budgets and achieve better returns on investment by ensuring their digital advertising efforts are effective and trustworthy.

Company Stage

IPO

Total Funding

$981.6M

Headquarters

New York City, New York

Founded

2008

Growth & Insights
Headcount

6 month growth

6%

1 year growth

10%

2 year growth

25%
Simplify Jobs

Simplify's Take

What believers are saying

  • DoubleVerify's recent partnerships and promotions, such as with Reddit and new leadership in APAC, indicate strong growth and expansion opportunities.
  • The company's advanced fraud detection capabilities, like uncovering the FM Scam, demonstrate their commitment to protecting clients' investments.
  • DoubleVerify's insights and research, such as the DV Global Insights Report, provide valuable data that can drive industry trends and client strategies.

What critics are saying

  • The investigation by Kirby McInerney LLP into potential violations of federal securities laws could impact DoubleVerify's reputation and financial stability.
  • The rapidly evolving digital advertising landscape requires continuous innovation, posing a challenge to maintain a competitive edge.

What makes DoubleVerify unique

  • DoubleVerify's dedicated Fraud Lab and Semantic Science teams provide advanced fraud detection and brand safety measures, setting them apart from competitors.
  • Their comprehensive media authentication services, including partnerships with platforms like Reddit, ensure ads are seen by real people in safe environments.
  • DoubleVerify's focus on analytics and verification services helps brands maximize their advertising budgets and achieve better returns on investment.